æ¬èšäºã¯ 2026 幎 3 æ 18 æ¥ ã«å
¬éãããã Scale fine-grained permissions across warehouses with Amazon Redshift and AWS IAM Identity Center ãã翻蚳ãããã®ã§ãã Amazon Redshift ã¯ããã«ãããŒãžãã§ãã¿ãã€ãèŠæš¡ã®ã¯ã©ãŠãããŒã¿ãŠã§ã¢ããŠã¹ã§ãåæã¯ãŒã¯ããŒãã容æã«ã¹ã±ãŒã«ã§ããŸããè€æ°ã®ããžãã¹ãŠãããã«ãŸããã£ãŠåææ©èœãæ¡åŒµããéãåãŠã§ã¢ããŠã¹ã®ãã现ããªã¢ã¯ã»ã¹èš±å¯ãå¹ççã«å®çŸ©ã»ç®¡çããææ³ãæ±ããããŸããå€ãã®çµç¹ã§ã¯ãMicrosoft Entra IDãOktaãPing ãªã©ã®å€éš ID ãããã€ã㌠(IdP) ã䜿çšããŠã¯ãŒã¯ãã©ãŒã¹ ID ãäžå
管çããŠãããäžè²«ããã¢ã¯ã»ã¹å¶åŸ¡ã§ããŒã¿ãŠã§ã¢ããŠã¹ãå¹ççã«çµ±åããå¿
èŠããããŸãããã®èª²é¡ã«å¯Ÿå¿ããããã Amazon Redshift ãã§ãã¬ãŒãããã¢ã¯ã»ã¹èš±å¯ ãš AWS IAM Identity Center ã®çµ±åãå°å
¥ãããŸãããã»ãã¥ãªãã£ããªã·ãŒãäžåºŠå®çŸ©ããã°ãã¢ã«ãŠã³ãå
ã®ãã¹ãŠã®ãŠã§ã¢ããŠã¹ã«èªåçã«é©çšã§ããŸãã Amazon Redshift ãã§ãã¬ãŒãããã¢ã¯ã»ã¹èš±å¯ã¯ãIAM Identity Center ãéããŠ è€æ°ã® AWS ãªãŒãžã§ã³ ã§å©çšã§ããããã«ãªããŸãããMicrosoft Entra IDãOktaãPing IdentityãOneLogin ãªã©ã®ãµããŒããããŠãã ID ãããã€ã㌠(IdP) ã® ID ããIAM Identity Center ãéããŠãµããŒããããŠãã AWS ãªãŒãžã§ã³éã§äœ¿çšã§ããŸããã¬ãžãªãšã³ã·ãŒããŠãŒã¶ãŒãžã®è¿æ¥æ§ãšãã£ãããžãã¹èŠä»¶ã«å¯Ÿå¿ã§ããŸããIAM Identity Center ããã©ã€ã㪠AWS ãªãŒãžã§ã³ãããããŒã¿ã¬ãžãã³ã·ãŒèŠä»¶ã«åºã¥ããŠè¿œå ã®ãªãŒãžã§ã³ã«æ¡åŒµã§ããããã«ãªããŸããããã®ãªãŒãžã§ã³ã§ã¯ãAmazon Redshift ãã§ãã¬ãŒãããã¢ã¯ã»ã¹èš±å¯ã䜿çšããŠè€æ°ã®ãŠã§ã¢ããŠã¹ã«æ°ãããŠã§ã¢ããŠã¹ã远å ããæ°Žå¹³æ¹åã®ãã«ããŠã§ã¢ããŠã¹ã¹ã±ãŒã©ããªãã£ãå®çŸã§ããŸããRedshift ãã§ãã¬ãŒãããã¢ã¯ã»ã¹èš±å¯ã§ã¯ããã®ãªãŒãžã§ã³å
ã®ä»»æã® Redshift ãŠã§ã¢ããŠã¹ããããŒã¿ã¢ã¯ã»ã¹èš±å¯ãäžåºŠå®çŸ©ããã°ããã®ãªãŒãžã§ã³ã®ã¢ã«ãŠã³ãå
ã®ãã¹ãŠã®ãŠã§ã¢ããŠã¹ã«èªåçã«é©çšãããŸãã æ¬èšäºã§ã¯ãAmazon Redshift ãã§ãã¬ãŒãããã¢ã¯ã»ã¹èš±å¯ãš AWS IAM Identity Center ãå®è£
ããè€æ°ã®ããŒã¿ãŠã§ã¢ããŠã¹ã«ãŸãããã¹ã±ãŒã©ãã«ãªããŒã¿ã¬ããã³ã¹ãå®çŸããæé ã玹ä»ããŸããEnterprise Data Warehouse (EDW) ããããã¥ãŒãµãŒããŒã¿ãŠã§ã¢ããŠã¹ãšããŠäžå
çãªããªã·ãŒå®çŸ©ãæã¡ãæåã§åèšå®ããããšãªã Sales ããã³ Marketing ã®ã³ã³ã·ã¥ãŒããŒããŒã¿ãŠã§ã¢ããŠã¹ã«ã»ãã¥ãªãã£ããªã·ãŒãèªåé©çšããã¢ãŒããã¯ãã£ã瀺ããŸãã以äžã®å
å®¹ãæ±ããŸãã ããŒã¿å
±æã®ãããã¥ãŒãµãŒãšã³ã³ã·ã¥ãŒããŒã®äž¡æ¹ã«å¯Ÿãã IAM Identity Center æ¥ç¶ã®èšå® Amazon Redshift Serverless åå空éã® AWS Glue Data Catalog ãžã®ç»é² ä¿¡é Œã§ãã ID ã®äŒæã®ã»ããã¢ãã åçããŒã¿ãã¹ãã³ã° ããªã·ãŒã®äœæãšã¢ã¿ããã«ããã顧客ã®çå¹Žææ¥ãªã©ã®å人æ
å ± (PII) ã®ä¿è· ãŠãŒã¶ãŒããŒã«ã«åºã¥ãããŒã¿ã®å¯èŠæ§ãå¶åŸ¡ãã è¡ã¬ãã«ã»ãã¥ãªã㣠ããªã·ãŒã®å®è£
IdP ã°ã«ãŒããã Amazon Redshift ããŒã¿ããŒã¹ããŒã«ãžã®ãããã³ã°ã«ããã·ãŒã ã¬ã¹ãªã¢ã¯ã»ã¹ç®¡ç åææ¡ä»¶ éå§åã«ä»¥äžã確èªããŠãã ããã 管çè
ããŒã«æš©éãæã€ AWS ã¢ã«ãŠã³ã äžèšã®ç®¡çè
ããŒã«ã«ããŒã¿ã¬ã€ã¯ç®¡çè
æš©éãå²ãåœãŠããæé ã«ã€ããŠã¯ã ããŒã¿ã¬ã€ã¯ç®¡çè
ã®äœæ ãåç
§ Lake Formation ã䜿çšãã IAM Identity Center çµ±å ãæå¹å AWS IAM Identity Center ãš Amazon Redshift Query Editor v2 ã®ã»ããã¢ããããã»ã¹ãçè§£ããããã ãã¡ãã®ããã°èšäº ãç¢ºèª AWS ã¢ã«ãŠã³ãã§ IAM Identity Center ãæå¹åããããœãªã¥ãŒã·ã§ã³æŠèŠãã»ã¯ã·ã§ã³ã®ããŠãŒã¶ãŒã¢ã¯ã»ã¹ã(å³ 2) ã«èšèŒãããŠãããŠãŒã¶ãŒãšã°ã«ãŒããäœæ Amazon Redshift ã¹ãŒããŒãŠãŒã¶ãŒãšããŠã AWSIDC:awssso-admin ããŒã¿ããŒã¹ããŒã«ã« CONNECT ãCREATE TABLEãINSERTãSELECTãsys:secadmin ã®æš©éãä»äž IAM Identity Center ã¢ã¯ã»ã¹çšã® IAM ããŒã«: ã¹ããã 1 : Amazon Redshift ã¢ã¯ã»ã¹çšã® IAM ããªã·ãŒãäœæãã ãAmazon Redshift ãš IAM Identity Center ãçµ±åãããããAmazon Redshift ããŒã¿ãŠã§ã¢ããŠã¹ãååšããã¢ã«ãŠã³ãã« IAM ããªã·ãŒ (äŸ: aws-idc-policy) ãäœæããŸãã { "Version": "2012-10-17", "Statement": [ { "Sid": "VisualEditor0", "Effect": "Allow", "Action": [ "redshift:DescribeQev2IdcApplications", "redshift-serverless:ListNamespaces", "redshift-serverless:ListWorkgroups", "redshift-serverless:GetWorkgroup" ], "Resource": [ "arn:aws:redshift-serverless:<AWS Region>:<AWS Account ID>:workgroup/*", "arn:aws:redshift-serverless:<AWS Region>:<AWS Account ID>:namespace/*" ] }, { "Sid": "VisualEditor1", "Effect": "Allow", "Action": [ "sso:DescribeApplication", "sso:DescribeInstance" ], "Resource": [ "arn:aws:sso:::instance/<IAM Identity Center Instance ID>", "arn:aws:sso::<AWS Account ID>:application/<IAM Identity Center Instance ID>/*" ] } ] } ã¹ããã 2 : IAM ããŒã«ãäœæãã ãAmazon Redshift ããŒã¿ãŠã§ã¢ããŠã¹ãååšããã¢ã«ãŠã³ãã« IAM ããŒã« (Amazon Redshift â ã«ã¹ã¿ãã€ãºå¯èœ) ãäœæããŸã (äŸ: IAMIDCRedshiftRole)ã ã¹ããã 3 : IAM ããªã·ãŒãããŒã«ã«ã¢ã¿ãããã ãäžèšã®ããŒã«ã«ä»¥äžã® 2 ã€ã® IAM ããªã·ãŒãã¢ã¿ããããŸãã aws-idc-policy AmazonRedshiftFederatedAuthorization ã¹ããã 4 : ä¿¡é Œé¢ä¿ãæŽæ°ãã ããã®ããŒã«ã®ä¿¡é Œé¢ä¿ã以äžã®ããã«æŽæ°ããŸãã { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "Service": "redshift.amazonaws.com" }, "Action": [ "sts:AssumeRole", "sts:SetContext" ] } ] } 泚æ: AmazonRedshiftFederatedAuthorization ã¯ãAmazon Redshift ãã§ãã¬ãŒãããèªå¯ã§ã¯ãšãªãå®è¡ããããã«å¿
èŠãªæš©éãæäŸãããããŒãžãããªã·ãŒã§ãã äžèšã® IAMIDCRedshiftRole IAM ããŒã«ããã¹ãŠã® Redshift Serverless ãšã³ããã€ã³ãã«ã¢ã¿ãã ãœãªã¥ãŒã·ã§ã³æŠèР以äžã®ã¢ãŒããã¯ãã£å³ã¯ããã«ããŠã§ã¢ããŠã¹ç°å¢ã§ã®ãã§ãã¬ãŒãããã¢ã¯ã»ã¹èš±å¯ã瀺ããŠãããã»ãã¥ãªãã£ããªã·ãŒãèªåé©çšããAmazon Redshift ãŠã§ã¢ããŠã¹å
šäœã§ã¹ã±ãŒã©ãã«ãªããŒã¿ã¬ããã³ã¹ãå®çŸããŸãã å³ 1: ãµã³ãã«ã¢ãŒããã¯ãã£å³ ãŠãŒã¶ãŒã¢ã¯ã»ã¹ ãŠãŒã¶ãŒã¯ãAmazon Redshift Query Editor v2ããµãŒãããŒãã£ã® SQL ãšãã£ã¿ãŒ (DBeaver ã SQL Workbench ãªã©)ããŸãã¯ã«ã¹ã¿ã ã¯ã©ã€ã¢ã³ãã¢ããªã±ãŒã·ã§ã³ãéããŠããŒã¿ãŠã§ã¢ããŠã¹ã«ã¢ã¯ã»ã¹ã§ããŸããã©ã®ã¢ã¯ã»ã¹æ¹æ³ã§ãäžè²«ããã»ãã¥ãªãã£ãé©çšãããŸãã å³ 2: ãœãªã¥ãŒã·ã§ã³æŠèŠãã㌠AWS IAM Identity Center ã®çµ±å IAM Identity Center ã¯ãã·ã³ã°ã«ãµã€ã³ãªã³ã«ããäžå
çãªèªèšŒãæäŸããçµç¹å
ã®ããŒã«ã«åºã¥ããŠæš©éãèªåçã«å²ãåœãŠãŸããID ãã§ãã¬ãŒã·ã§ã³ã«ããäŒæ¥ã® ID ã AWS ãªãœãŒã¹ã«çŽæ¥ãªã³ã¯ããããŠã§ã¢ããŠã¹ãžã®ã¢ã¯ã»ã¹åã«èªèšŒãè¡ãããŸãã ãã«ããŠã§ã¢ããŠã¹ã¢ãŒããã¯ã㣠ãã®ã¢ãŒããã¯ãã£ã§ã¯ãç°ãªãããžãã¹æ©èœãæã¡ã€ã€ãã»ãã¥ãªãã£ããªã·ãŒãå
±æãã 3 ã€ã®ããŒã¿ãŠã§ã¢ããŠã¹ã䜿çšããŸãã Enterprise Data Warehouse (EDW) EDW ã¯ããšã³ã¿ãŒãã©ã€ãºããŒã¿ã®äžå€®ãªããžããªã§ãã顧客ããŒã¿ãšè£œåããŒã¿ã¯ Customer Profile Database (CPD) ã«æ ŒçŽãããŠããã管çè
㯠2 ã€ã®ã»ãã¥ãªãã£ããªã·ãŒãå®çŸ©ããŸãã åçããŒã¿ãã¹ãã³ã° (DDM) â Sales Analyst ãš Marketing Analyst ã®äž¡æ¹ã®ããŒã«ã«å¯ŸããŠã顧客ã®çå¹Žææ¥ (DOB) ãã£ãŒã«ãããã¹ãã³ã°ããåæäœæ¥ã劚ããã«å人æ
å ± (PII) ãä¿è·ããŸã è¡ã¬ãã«ã»ãã¥ãªã㣠(RLS) â ãŠãŒã¶ãŒããŒã«ã«åºã¥ããŠè£œåã®å¯èŠæ§ãå¶åŸ¡ããŸããSales Analyst 㯠launched (çºå£²æžã¿) ã®è£œåã®ã¿è¡šç€ºã§ããMarketing Analyst 㯠launched ãš planned (èšç»äž) ã®äž¡æ¹ã®è£œåã衚瀺ã§ããŸã EDW 㯠AWS Glue Data Catalog ã«ç»é²ãããçµ±åã¡ã¿ããŒã¿ãªããžããªãäœæããã¢ã«ãŠã³ãå
ã®ãŠã§ã¢ããŠã¹å
šäœã§ããŒã¿ãæ€åºå¯èœã«ããŸãããã®ç»é²ããã§ãã¬ãŒãããã¢ã¯ã»ã¹èš±å¯ã®åºç€ãšãªããããªã·ãŒãèªåäŒæã§ããŸãã Sales ããŒã¿ãŠã§ã¢ããŠã¹ Sales Analyst ã顧客ããŒãã«ãšè£œåããŒãã«ãã¯ãšãªãããšããã§ãã¬ãŒãããã¢ã¯ã»ã¹èš±å¯ã«ãã EDW ã§å®çŸ©ããããªã·ãŒãèªåçã«é©çšãããŸããEDW ã®ç»é²æžã¿åå空éãå€éšããŒã¿ããŒã¹ãšããŠèªåããŠã³ãããããããããªã·ãŒã®åäœæãåã¢ã¿ããã¯äžèŠã§ãã顧客㮠DOB ãã£ãŒã«ãã¯ãã¹ãã³ã°ããã launched ã®è£œåã®ã¿ã衚瀺ãããŸãã远å èšå®ã¯äžèŠã§ãã Marketing ããŒã¿ãŠã§ã¢ããŠã¹ Marketing ããŒã¿ãŠã§ã¢ããŠã¹ã EDW ã®ã»ãã¥ãªãã£ããªã·ãŒãèªåçã«ç¶æ¿ããŸãã顧客㮠DOB ãã£ãŒã«ã㯠PII ä¿è·ã®ãããã¹ãã³ã°ããããŸãŸã§ãããRLS ããªã·ãŒã«ãã Marketing Analyst 㯠launched ãš planned ã®äž¡æ¹ã®è£œåã衚瀺ã§ããŸããããŒã±ãã£ã³ã°èšç»ã«å¿
èŠãªåºç¯ãªå¯èŠæ§ã確ä¿ãããŸããã¢ã¯ã»ã¹å¶åŸ¡ã¯ãŠãŒã¶ãŒããŒã«ã«åºã¥ããŠèªåçã«é©çšãããŸãã ãŠã©ãŒã¯ã¹ã«ãŒ ããã§ã¯ 2 ã€ã® Amazon Redshift IAM Identity Center (IDC) æ¥ç¶ãäœæããŸãã ããŒã¿å
±æãããã¥ãŒãµãŒ Identity Center æ¥ç¶ â edw-wg Amazon Redshift Serverless ã¯ãŒã¯ã°ã«ãŒãã«å²ãåœãŠ ããŒã¿å
±æã³ã³ã·ã¥ãŒã㌠Identity Center æ¥ç¶ â cpd-sales-wg ããã³ cpd-marketing-wg Amazon Redshift Serverless ã¯ãŒã¯ã°ã«ãŒãã«å²ãåœãŠ Amazon Redshift ãã§ãã¬ãŒãããã¢ã¯ã»ã¹èš±å¯çšã® IDC æ¥ç¶ãã»ããã¢ãããã ãŠã§ã¢ããŠã¹éã®ãã§ãã¬ãŒãããèªèšŒãæå¹ã«ãã IAM Identity Center æ¥ç¶ãèšå®ããŸãããããã¥ãŒãµãŒ (ããªã·ãŒå®çŸ©) ãŠã§ã¢ããŠã¹ãšã³ã³ã·ã¥ãŒããŒãŠã§ã¢ããŠã¹çšã«åå¥ã®æ¥ç¶ãäœæããŸãã Amazon Redshift ããŒã¿å
±æãããã¥ãŒãµãŒ IDC æ¥ç¶ãèšå®ãã ãããã¥ãŒãµãŒ IDC æ¥ç¶ãäœæããã«ã¯: Amazon Redshift Serverless ã³ã³ãœãŒã« ãéããŸãã ãã³ããŒã¬ãŒã¡ãã¥ãŒãå±éã㊠IAM Identity Center connections ãéžæããŸãã Create application ãéžæããŸãã ãAmazon Redshift connected to IAM Identity Centerããšè¡šç€ºãããŠããããšã確èªãã Next ãéžæããŸãã æ¥ç¶ããããã£ãèšå®ããŸãã IAM Identity Center display name ã«ååãå
¥åããŸãã Managed application name ã« rs-multicluster-producer ãšå
¥åããŸãã Identity provider namespace ã§ AWSIDC ãéžæããŸãã IAM role for IAM Identity Center access ã§ãäœæãã IAM ããŒã«ãéžæããŸãã Query editor v2 application ã§ Enable the query editor v2 application ãéžæããŸãã IAM Identity Center application type ã§ Configure Amazon Redshift federated permissions using AWS IAM Identity Center (Recommended) ãéžæããŸãã Next ãéžæããŸãã Configure client connections that use third-party IdPs ã§ No ãéžæããŸãã Next ãéžæããŸãã èšå®å
容ã確èªãã Create Application ãéžæããŸãã å³ 3: ããŒã¿å
±æãããã¥ãŒãµãŒ IDC æ¥ç¶ ããŒã¿å
±æã³ã³ã·ã¥ãŒã㌠IDC æ¥ç¶ãèšå®ãã ã³ã³ã·ã¥ãŒã㌠IDC æ¥ç¶ãäœæããã«ã¯: Amazon Redshift Serverless ã³ã³ãœãŒã« ãéããŸãã ãã³ããŒã¬ãŒã¡ãã¥ãŒãå±éã㊠IAM Identity Center connections ãéžæããŸãã Create application ãéžæããŸãã ãAmazon Redshift connected to IAM Identity Centerããšè¡šç€ºãããŠããããšã確èªãã Next ãéžæããŸãã æ¥ç¶ããããã£ãèšå®ããŸãã IAM Identity Center display name ã«ååãå
¥åããŸãã Managed application name ã« rs-multicluster-consumer ãšå
¥åããŸãã Identity provider namespace ã§ AWSIDC ãéžæããŸãã IAM role for IAM Identity Center access ã§ãäœæãã IAM ããŒã«ãéžæããŸãã Query editor v2 application ã«ã¯ãYou already have a query editor v2 application.ããšããéç¥ã衚瀺ãããŸãã IAM Identity Center application type ã§ Configure Amazon Redshift federated permissions using AWS IAM Identity Center (Recommended) ã®éžæã è§£é€ ããŸãã Trusted identity propagation ã§ AWS Lake Formation access grants ãš Amazon Redshift Connect ãéžæããŸãã Next ãéžæããŸãã Configure client connections that use third-party IdPs ã§ No ãéžæããŸãã Next ãéžæããŸãã èšå®å
容ã確èªãã Create Application ãéžæããŸãã Amazon Redshift ããŒã¿å
±æã³ã³ã·ã¥ãŒããŒã® IDC ã¢ããªã±ãŒã·ã§ã³ã«å¿
èŠãªãŠãŒã¶ãŒãŸãã¯ã°ã«ãŒãã远å ããŸãã å³ 4: ããŒã¿å
±æã³ã³ã·ã¥ãŒã㌠IDC æ¥ç¶ Amazon Redshift Serverless åå空éã«å¯ŸããããŒã¿å
±æãããã¥ãŒãµãŒ IDC æ¥ç¶ãèšå®ãã ãã§ãã¬ãŒãããã¢ã¯ã»ã¹èš±å¯ã§ edw-ns åå空éãç»é²ããã«ã¯: Amazon Redshift Serverless Namespace ã³ã³ãœãŒã« ãéããŸãã Amazon Redshift Serverless åå空éãéžæããŸãã Actions ãéžæãã Register with AWS Glue Data Catalog ãéžæããŸãã Register with Amazon Redshift federated permissions ãéžæããŸãã Amazon Redshift federated permissions using AWS IAM Identity Center ãéžæããŸãã Register ãéžæããŸãã å³ 5: Amazon Redshift ããŒã¿ãŠã§ã¢ããŠã¹ã® Glue Data Catalog ãžã®ç»é² å³ 6: Amazon Redshift ããŒã¿ãŠã§ã¢ããŠã¹ã® Glue Data Catalog ãžã®ç»é² 泚æ: äœæããããŒã¿å
±æãããã¥ãŒãµãŒ IDC æ¥ç¶ã® IAM Identity Center ãããŒãžãã¢ããªã±ãŒã·ã§ã³ ARN ã䜿çšãããŸãã æ¢åã® Serverless åå空éã«å¯ŸããããŒã¿å
±æã³ã³ã·ã¥ãŒã㌠IDC æ¥ç¶ãèšå®ãã cpd-sales-wg ãš cpd-marketing-wg ã® Serverless ã¯ãŒã¯ã°ã«ãŒãã«ã€ããŠãç»é²æžã¿ã® IAM Identity Center æ¥ç¶ãã以äžã®æ
å ±ãåéããŸãã IAM Identity Center display name Identity provider namespace IAM Identity Center managed application ARN IAM role for IAM Identity Center access ããŒã¿ããŒã¹ç®¡çè
ãšããŠä»¥äžã® SQL ã³ãã³ããå®è¡ããçµ±åãæå¹ã«ããŸãã CREATE IDENTITY PROVIDER "<IAM Identity Center display name>" TYPE AWSIDC NAMESPACE '<Identity provider namespace>' APPLICATION_ARN '<IAM Identity Center managed application ARN>' IAM_ROLE '<IAM role for IAM Identity Center access>'; æ¢åã® ID ãããã€ããŒã倿Žããã«ã¯ãALTER IDENTITY PROVIDER ã³ãã³ãã䜿çšããŸãã ALTER IDENTITY PROVIDER "<IAM Identity Center display name>" NAMESPACE '<Identity provider namespace>'; ALTER IDENTITY PROVIDER "<IAM Identity Center display name>" IAM_ROLE default | '<IAM role for IAM Identity Center access>'; ãããã¥ãŒãµãŒã§ã®ããŒã¿æºåãšã¢ã¯ã»ã¹èšå® 顧客ããŒãã«ãšè£œåããŒãã«ãäœæãããµã³ãã«ããŒã¿ãããŒãããDDM ãš RLS ããªã·ãŒãäœæããŠããŒã¿ããŒã¹ããŒã«ã«ã¢ã¿ããããSELECT æš©éãä»äžããŸãã EDW ã§ããŒã¿ãæºåãã IDC Admin ãŠãŒã¶ãŒãšã㊠EDW ããŒã¿ãŠã§ã¢ããŠã¹ã«æ¥ç¶ãã以äžã® SQL ã³ãã³ããå®è¡ããŸãã product ããŒãã«ãäœæããŸãã CREATE TABLE product ( product_id VARCHAR(16) NOT NULL, product_desc VARCHAR(200), current_price NUMERIC(7,2), wholesale_cost NUMERIC(7,2), category_desc VARCHAR(50), launch_status VARCHAR(50) ); ãµã³ãã«ã® product ããŒã¿ãæ¿å
¥ããŸãã INSERT INTO product VALUES ('AAAAAAAAAFNPEAAA','At least concerned authors adopt just brown, federal',7.12,4.12,'Jewelry','launched'), ('AAAAAAAAOAAGDAAA','Complex services may not find totally changing accountants. Tiny, available ministers could not know always systems. Hot, male speakers discer',8.08,5.49,'Shoes','planned'), ('AAAAAAAAMJJMCAAA','Rows could prevent political, old duties. Just international stairs would regret police. Conditions discard always interesting, warm years. Present jobs shall take nearby relatively dreadful',8.18,5.31,'Jewelry','launched'), ('AAAAAAAAKLBLBAAA','Suddenly external sentences believe then by the assets. Simultaneously young feet could not probe separately shortly new men. Forms work again individuals. Images',17.96,7.9,'Shoes','launched'), ('AAAAAAAAMBKMCAAA','Clubs see finally materials. Significant objectives sell fairly left, civil power',3.18,3.84,'Books','launched'), ('AAAAAAAACPCAAAAA','Perhaps past preferences tell rather to a accounts. Very common feet can command never available final years; minutes expect recent, due employers. Altogether english shoes',9.84,0.19,'Electronics','planned'), ('AAAAAAAAFOIABAAA','More responsible characters go left factors. Championships shall stand twice new, important shows. Books could receive too able, national pounds. Central',3.55,2.2,'Books','launched'), ('AAAAAAAAKGBIAAAA','High, political changes shall not',9.55,5.25,'Electronics','launched'); customer ããŒãã«ãäœæããŸãã CREATE TABLE customer ( customer_id VARCHAR(16), first_name VARCHAR(20), last_name VARCHAR(30), date_of_birth VARCHAR(32), birth_country VARCHAR(20), email_address VARCHAR(50) ); ãµã³ãã«ã® customer ããŒã¿ãæ¿å
¥ããŸãã INSERT INTO customer VALUES ('AAAAAAAALAMKHGBA','Regina','Coleman','1926-12-17','GAMBIA','Regina.Coleman@JFFRohn.edu'), ('AAAAAAAAMCMKHGBA','John','Bell','1980-01-07','PAPUA NEW GUINEA','John.Bell@uAR3ReP6yi9eDyq.edu'), ('AAAAAAAANNMKHGBA','Jacqueline','Pierre','1951-12-18','SAMOA','Jacqueline.Pierre@UQcHfFDEVdj.com'), ('AAAAAAAANFNKHGBA','Frank','Mackay','1992-03-19','HONG KONG','Frank.Mackay@MzAI.edu'), ('AAAAAAAAOGNKHGBA','Anthony','Miller','1948-02-26','ALGERIA','Anthony.Miller@pF.edu'), ('AAAAAAAACPOKHGBA','Bradley','Sawyer','1956-12-25','ZAMBIA','Bradley.Sawyer@kAXu5U1MrRRkAqP.edu'), ('AAAAAAAAOIPKHGBA','Robert','Carter','1951-01-01','UNITED STATES','Robert.Carter@Z.org'), ('AAAAAAAALJPKHGBA','Ola','High','1980-11-19','SUDAN','Ola.High@N.org'); DDM ãš RLS ããªã·ãŒãäœæãã customer ã®çå¹Žææ¥ã«å¯Ÿãããã¹ãã³ã°ããªã·ãŒãäœæããŸãã CREATE MASKING POLICY mask_cust_dob WITH (date_of_birth VARCHAR(32)) USING (sha2(date_of_birth, 256)::TEXT); product ã® launch_status ã«å¯Ÿãã RLS ããªã·ãŒãäœæããŸãã CREATE RLS POLICY product_launch_status WITH (launch_status VARCHAR(50)) USING (launch_status = 'launched'); CREATE RLS POLICY product_launch_status_all WITH (launch_status VARCHAR(50)) USING (launch_status IN ('launched','planned')); Sales ã°ã«ãŒããš Marketing ã°ã«ãŒãçšã® Amazon Redshift DB ããŒã«ãäœæãã ããŒã¿ããŒã¹ããŒã«ãäœæããŸãã CREATE ROLE "AWSIDC:awssso-sales"; CREATE ROLE "AWSIDC:awssso-marketing"; ãã¹ãã³ã°ããªã·ãŒãã¢ã¿ãããã äž¡æ¹ã®ããŒã«ã«ãã¹ãã³ã°ããªã·ãŒãã¢ã¿ããããŸãã ATTACH MASKING POLICY mask_cust_dob ON dev.public.customer (date_of_birth) TO ROLE "AWSIDC:awssso-marketing"; ATTACH MASKING POLICY mask_cust_dob ON dev.public.customer (date_of_birth) TO ROLE "AWSIDC:awssso-sales"; RLS ããªã·ãŒãã¢ã¿ããããproduct ããŒãã«ã§ RLS ãæå¹ã«ãã RLS ããªã·ãŒãã¢ã¿ããããè¡ã¬ãã«ã»ãã¥ãªãã£ãæå¹ã«ããŸãã ATTACH RLS POLICY product_launch_status ON dev.public.product TO ROLE "AWSIDC:awssso-sales"; ATTACH RLS POLICY product_launch_status_all ON dev.public.product TO ROLE "AWSIDC:awssso-marketing"; ALTER TABLE dev.public.product ROW LEVEL SECURITY ON; ããŒãã«ãžã®ã¢ã¯ã»ã¹æš©ãããŒã«ã«ä»äžãã äž¡æ¹ã®ããŒã«ã« SELECT æš©éãä»äžããŸãã GRANT SELECT ON dev.public.customer TO ROLE "AWSIDC:awssso-sales"; GRANT SELECT ON dev.public.customer TO ROLE "AWSIDC:awssso-marketing"; GRANT SELECT ON dev.public.product TO ROLE "AWSIDC:awssso-sales"; GRANT SELECT ON dev.public.product TO ROLE "AWSIDC:awssso-marketing"; IAM Identity Center ã䜿çšã㊠Sales ããŒã¿ãŠã§ã¢ããŠã¹ã«æ¥ç¶ãã Sales Analyst ãšããŠæ¥ç¶ããã«ã¯: IAM Identity Center æ¥ç¶ã¿ã€ãã䜿çšããŠããŠãŒã¶ãŒ sales-analyst ãšã㊠cpd-sales-wg ã«æ¥ç¶ãã Continue ãéžæããŸãã sales-analyst ãéžæãã Next ãéžæããŸãã ãã¹ã¯ãŒããå
¥åãã Sign in ãéžæããŸãã MFA ã³ãŒããå
¥åãã Sign in ãéžæããŸãã Amazon Redshift Query Editor V2 ã§ sales-analyst ãšã㊠cpd-sales-wg ã«æ¥ç¶ã§ããŸããã å³ 7: IDC ãŠãŒã¶ãŒãšã㊠Sales ããŒã¿ãŠã§ã¢ããŠã¹ã«æ¥ç¶ Sales Analyst ãšããŠå
±æããŒã¿ãã¯ãšãªãã åçããŒã¿ãã¹ãã³ã°ãé©çšããã customer ããŒãã«ãã¯ãšãªããŸãã SELECT * FROM "dev@edw-ns"."public"."customer"; customer ããŒãã«ã«ã¢ã¯ã»ã¹ã§ããŸããã date_of_birth åã®æ©å¯æ
å ±ã¯æå·åãããŠããŸãã å³ 8: customer ããŒãã«ã®çµæã»ãã è¡ã¬ãã«ã»ãã¥ãªãã£ãæå¹ãª product ããŒãã«ãã¯ãšãªããŸãã SELECT * FROM "dev@edw-ns"."public"."product"; product ããŒãã«ã«ã¢ã¯ã»ã¹ã§ããŸããã launch_status ã launched ã®è£œåã®ã¿è¡šç€ºãããŸãã å³ 9: product ããŒãã«ã®çµæã»ãã æ³šæ: Amazon Redshift ãã§ãã¬ãŒãããã¢ã¯ã»ã¹èš±å¯ã«ãªã³ããŒããããããŒã¿å
±æãããã¥ãŒãµãŒã« IDC ãŠãŒã¶ãŒãšããŠæ¥ç¶ããã«ã¯ãã¹ãŒããŒãŠãŒã¶ãŒãæ¥ç¶ããããšãã IDC ãŠãŒã¶ãŒã« CONNECT æš©éãä»äžããå¿
èŠããããŸããCONNECT æš©éã®ä»äžæ¹æ³ã«ã€ããŠã¯ãAmazon Redshift ããŒã¿ããŒã¹ããããããŒã¬ã€ãã® Connect privileges ãåç
§ããŠãã ããã IAM Identity Center ã䜿çšã㊠Marketing ããŒã¿ãŠã§ã¢ããŠã¹ã«æ¥ç¶ãã Marketing Analyst ãšããŠæ¥ç¶ããã«ã¯: IAM Identity Center æ¥ç¶ã¿ã€ãã䜿çšããŠããŠãŒã¶ãŒ marketing-analyst ãšã㊠cpd-marketing-wg ã«æ¥ç¶ãã Continue ãéžæããŸãã marketing-analyst ãéžæãã Next ãéžæããŸãã ãã¹ã¯ãŒããå
¥åãã Sign in ãéžæããŸãã MFA ã³ãŒããå
¥åãã Sign in ãéžæããŸãã Amazon Redshift Query Editor V2 ã§ marketing-analyst ãšã㊠cpd-marketing-wg ã«æ¥ç¶ã§ããŸããã å³ 10: IDC ãŠãŒã¶ãŒãšã㊠Marketing ããŒã¿ãŠã§ã¢ããŠã¹ã«æ¥ç¶ Marketing Analyst ãšããŠå
±æããŒã¿ãã¯ãšãªãã åçããŒã¿ãã¹ãã³ã°ãé©çšããã customer ããŒãã«ãã¯ãšãªããŸãã SELECT * FROM "dev@edw-ns"."public"."customer"; customer ããŒãã«ã«ã¢ã¯ã»ã¹ã§ããŸããã date_of_birth åã®æ©å¯æ
å ±ã¯æå·åãããŠããŸãã å³ 11: customer ããŒãã«ã®çµæã»ãã è¡ã¬ãã«ã»ãã¥ãªãã£ãæå¹ãª product ããŒãã«ãã¯ãšãªããŸãã SELECT * FROM "dev@edw-ns"."public"."product"; product ããŒãã«ã«ã¢ã¯ã»ã¹ã§ãã launch_status ã launched ãš planned ã®äž¡æ¹ã®è£œåã衚瀺ã§ããŸãã å³ 12: product ããŒãã«ã®çµæã»ãã 远å ãªãœãŒã¹ ãã§ãã¬ãŒãããã¢ã¯ã»ã¹èš±å¯ã®å®è£
ã«ã€ããŠè©³ããã¯ã以äžã®ãªãœãŒã¹ãåç
§ããŠãã ããã AWS ããã¥ã¡ã³ã Amazon Redshift ãã§ãã¬ãŒãããã¢ã¯ã»ã¹èš±å¯ Amazon Redshift ã¯ãšãªãšãã£ã¿ v2 ããã®æ¥ç¶ã®ãã©ãã«ã·ã¥ãŒãã£ã³ã° AWS ããã° Amazon Redshift ãã§ãã¬ãŒãããã¢ã¯ã»ã¹èš±å¯ã§ãã«ããŠã§ã¢ããŠã¹ã®ããŒã¿ã¬ããã³ã¹ãç°¡çŽ åãã Integrate Identity Provider (IdP) with Amazon Redshift Query Editor V2 and SQL Client using AWS IAM Identity Center for seamless Single Sign-On AWS ã㢠Introducing Amazon Redshift Federated Permissions äž»ãªã¡ãªãã 管çè² è·ã®åæž â ããªã·ãŒãäžå
管çããæåã§ã®è€è£œãäžèŠã«ãªããŸã äžè²«ããã»ãã¥ãªãã£ã®é©çš â ãŠã§ã¢ããŠã¹ãã¢ã¯ã»ã¹æ¹æ³ãåãããããªã·ãŒãåäžã«é©çšãããŸã ID ã®ã·ãŒã ã¬ã¹ãªçµ±å â ä¿¡é Œããã ID äŒæãšããŒã«ããŒã¹ã®ã¢ã¯ã»ã¹å¶åŸ¡ã§ãæ¢åã® ID ãããã€ããŒãšã®ã·ã³ã°ã«ãµã€ã³ãªã³ãå®çŸããŸã ãŸãšã æ¬èšäºã§ã¯ãAmazon Redshift ãã§ãã¬ãŒãããã¢ã¯ã»ã¹èš±å¯ãš AWS IAM Identity Center ã®çµ±åã«ãããã»ãã¥ãªãã£ããªã·ãŒãäžå
管çãããã«ããŠã§ã¢ããŠã¹ã®ããŒã¿ã¬ããã³ã¹ãå¹çåããæ¹æ³ã玹ä»ããŸãããåçããŒã¿ãã¹ãã³ã°ãšè¡ã¬ãã«ã»ãã¥ãªãã£ã®ããªã·ãŒã Enterprise Data Warehouse ã§äžåºŠå®çŸ©ããã°ãåãã¢ã«ãŠã³ããšãªãŒãžã§ã³å
ã®æ¥ç¶å
ããŒã¿ãŠã§ã¢ããŠã¹ã«èªåé©çšãããŸãã èè
ã«ã€ã㊠Raghu Kuppala Raghu ã¯ãããŒã¿ããŒã¹ãããŒã¿ãŠã§ã¢ããŠãžã³ã°ãåæåéã®çµéšãæã€ Analytics Specialist Solutions Architect ã§ããä»äºä»¥å€ã§ã¯ãããŸããŸãªæçã詊ããããå®¶æãå人ãšéããããšã楜ããã§ããŸãã Satesh Sonti Satesh ã¯ãã¢ãã©ã³ã¿ãæ ç¹ãšãã Principal Specialist Solutions Architect ã§ããšã³ã¿ãŒãã©ã€ãºããŒã¿ãã©ãããã©ãŒã ãããŒã¿ãŠã§ã¢ããŠãžã³ã°ãåæãœãªã¥ãŒã·ã§ã³ã®æ§ç¯ãå°éãšããŠããŸããäžçäžã®éè¡ã»ä¿éºæ¥çã®ã¯ã©ã€ã¢ã³ãåãã«ãããŒã¿è³ç£ã®æ§ç¯ãè€éãªããŒã¿ãã©ãããã©ãŒã ããã°ã©ã ã®ãªãŒãã« 20 幎以äžã®çµéšããããŸãã Sandeep Adwankar Sandeep ã¯ãAmazon SageMaker Lakehouse ã® Senior Product Manager ã§ããã«ãªãã©ã«ãã¢ã®ãã€ãšãªã¢ãæ ç¹ã«ãäžçäžã®ã客æ§ãšé£æºããŠããžãã¹ããã³æè¡èŠä»¶ã補åã«åæ ããããŒã¿ã®ç®¡çãã»ãã¥ãªãã£ãã¢ã¯ã»ã¹ã®æ¹åãæ¯æŽããŠããŸãã Sumukh Bapat Sumukh ã¯ãAWS ã®ãœãããŠã§ã¢ãšã³ãžãã¢ã§ããèªèšŒãæ¥ç¶æ§ãã»ãã¥ãªãã£ã«ãããè€éãªåé¡ã解決ããAmazon Redshift ã®ã«ã¹ã¿ããŒãšã¯ã¹ããªãšã³ã¹åäžã«åãçµãã§ããŸããID 管çãã»ãã¥ã¢ã¢ã¯ã»ã¹ã忣ããŒã¿ããŒã¹ã·ã¹ãã ã«æ³šåããŠããŸãã Praveen Kumar Ramakrishnan Praveen ã¯ãAWS ã®ã·ãã¢ãœãããŠã§ã¢ãšã³ãžãã¢ã§ãããã¡ã€ã«ã·ã¹ãã ãã¹ãã¬ãŒãžä»®æ³åããããã¯ãŒã¯ã»ãã¥ãªãã£ãªã©ãããŸããŸãªåéã§çŽ 20 幎ã®çµéšããããŸããAWS ã§ã¯ Redshift ã®ããŒã¿ã»ãã¥ãªãã£åŒ·åã«æ³šåããŠããŸãã Ashish Ghodke Ashish ã¯ãAmazon Web Services ã®ãœãããŠã§ã¢ãšã³ãžãã¢ã§ãAmazon Redshift ãªã©ã®å€§èŠæš¡ã¯ã©ãŠããµãŒãã¹åãã® ID ããã³ã¢ã¯ã»ã¹ç®¡çã·ã¹ãã ã«åãçµãã§ããŸãã忣ã·ã¹ãã åãã®ã»ãã¥ã¢ãªèªèšŒãšã·ã³ã°ã«ãµã€ã³ãªã³ãœãªã¥ãŒã·ã§ã³ã®æ§ç¯ã«æ³šåããŠããŸãã忣ã·ã¹ãã ãã¯ã©ãŠãã»ãã¥ãªãã£ãã¹ã±ãŒã©ãã«ã§ä¿¡é Œæ§ã®é«ãã€ã³ãã©ã¹ãã©ã¯ãã£ã®æ§ç¯ã«æ
ç±ãæã£ãŠããŸãã ãã®èšäºã¯ Kiro ã翻蚳ãæ
åœããSolutions Architect ã® Kenji Hirai ãã¬ãã¥ãŒããŸããã